{"repo":"JamesWoolfenden/ghat","free":true,"listed":false,"github":"https://github.com/JamesWoolfenden/ghat","clone":"git clone https://github.com/JamesWoolfenden/ghat.git","description":"Ghat is a tool for updating your GitHub actions and Terraform with the latest version of it dependencies and using immutable hashes instead of mutable tags.","language":"Go","stars":25,"topics":["cicd","github-actions","hashes","iac","terraform"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"ghat Ghat is a tool (GHAT) for updating dependencies in GitHub Actions, GitLab CI/CD, Kubernetes manifests, managing Terraform module and provider versions , and pre-commit configs. It replaces insecure mutable tags with immutable commit hashes and container image digests, and updates provider versions to their latest stable releases: Becomes Ghat will use your GitHub credentials, if available, from your environment using the environmental variables GITHUB TOKEN or GITHUB API, but it can also drop back to anonymous access, the drawback is that this is severely rate limited by gitHub. Ghat also manages GitLab CI/CD container images by replacing mutable tags with immutable SHA256 digests: Becomes: It manages Terraform provider versions by querying the Terraform Registry and updating to the latest stable versions: Becomes: And it manages Terraform modules, to give you the most secure reference, so: Becomes: New to ghat? Start with the hands-on tutorial — it walks you from first pin to org-wide rollout. Table of Contents - ghat - Table of Contents - Install - MacOS - Windows - Docker - Usage - swot - directory - file - stable - stun - directory scan - dry-run - shake - directory scan - file scan - swipe - sift - kube - sweep - audit - org - pre-commit Install Download the latest binary here: Install from code: - Clone repo - Run go install Install remotely: MacOS Windows I'm now using Scoop to distribute releases, it's much quicker to update and easier to manage than previous met","default_branch":null,"files":null,"tree":[],"storefront":"/r/JamesWoolfenden","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/JamesWoolfenden/ghat/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}